Available for Opportunities

MSK.

Sr. Information Security Analyst | Cybersecurity GRC

I'm Madhava Sai Kolluri — a Sr. Information Security Analyst with 9+ years of experience that started in data operations and grew into full-scale cybersecurity governance, risk management, and cloud security.

I've built SSPs from scratch, led risk assessments that uncovered real control deficiencies, and driven POA&M remediation that consistently closed findings ahead of schedule. Whether it's writing security controls, coordinating with engineering, or sitting across from auditors — I focus on delivering documentation and governance outcomes that actually hold up under scrutiny.

NIST SP 800-53 RMF Cloud Security IAM / RBAC RSA Archer GRC
Madhavaa
9+
Years Exp
200+
Controls Mapped
3
ATO Approvals

Timeline // Protocol History

Professional journey and career milestones

SEP 2025 - PRESENT

Sr. Information Security Analyst

Alipro — Remote, Bloomington, IL

Writing and maintaining full SSP and IT control documentation for an Azure-hosted platform. Drove end-to-end NIST RMF activities that helped clear ATO two weeks ahead of schedule. Mapped 200+ controls to NIST SP 800-53 families, cutting audit prep time by 40%.

Azure
NIST RMF
SSP
FedRAMP
Power BI
DEC 2021 - SEP 2025

Sr. Information Security Engineer Analyst

United Health Group (Optum) — Hyderabad, India

Developed and maintained SSPs for FISMA-regulated healthcare platforms compliant with NIST SP 800-53, MARS-E, and ARC-AMPE. Supported A&A processes helping three major systems achieve ATO on time. Created golden templates that cut SSP drafting time by 30%.

RSA Archer
FISMA
MARS-E
HIPAA
AWS
JUL 2020 - SEP 2021

Sr. Reporting Analyst

Infinity Education Consultants — Hyderabad, India

Managed IAM and access governance for an Azure PaaS CRM. Designed Entra ID RBAC models, enforced MFA and Conditional Access policies, reducing unauthorized access attempts by 60%. Monitored identity alerts via Microsoft Sentinel.

Entra ID
Sentinel
RBAC
IAM
OCT 2018 - APR 2019

AWS Cloud Security Engineer

Storyqube / Voiceqube — Hyderabad, India

Engineered cloud security controls for a voice-based mobile platform on AWS. Hardened S3 buckets with encryption and access policies. Implemented centralized logging via CloudTrail and CloudWatch for anomaly detection.

AWS
S3
CloudTrail
Splunk
Nessus
OCT 2017 - OCT 2018

Associate

Wipro / Google — Hyderabad, India

Verified and enriched geospatial datasets across 5+ map enhancement projects. Proposed a validation checklist adopted by the team that reduced error rates by 20%.

Data Quality
GIS
Validation

Skill Matrix // Core Competencies

Technical expertise and domain knowledge

description

GRC & Compliance

NIST 800-53 RMF FedRAMP FISMA

Proficiency

cloud_sync

Cloud Security

Azure AWS GCP

Proficiency

shield

IAM & Zero Trust

Entra ID RBAC MFA CA Policy

Proficiency

verified_user

A&A & ATO

SSP SAR POA&M Archer

Proficiency

radar

SIEM & Monitoring

Sentinel QRadar Splunk Nessus

Proficiency

build

Tools & Reporting

Power BI SNOW JIRA SPO

Proficiency

Operation Log // Key Projects

Recent projects and successful implementations

01 verified_user

ATO Acceleration — Azure

Drove NIST RMF from FIPS 199 through continuous monitoring. Mapped 200+ controls, cleared ATO two weeks early with 95% acceptance.

NIST RMF ATO Azure
200+ controls mapped
02 description

Enterprise Healthcare SSP

Built SSPs for FISMA-regulated healthcare platforms at Optum. Created golden templates cutting drafting time by 30%. Helped 3 systems achieve ATO.

SSP FISMA MARS-E Archer
3 ATO approvals
03 shield

IAM Governance — Azure CRM

Designed Entra ID RBAC models, enforced MFA and Conditional Access. Reduced unauthorized access by 60%.

Entra ID RBAC Sentinel
-60% unauth access
04 cloud

AWS Cloud Hardening

Engineered security controls for voice platform. Hardened S3 with SSE-KMS, implemented CloudTrail logging.

AWS S3 CloudTrail
05 monitoring

Security Dashboards

Built Power BI dashboards consolidating incident, access review, and remediation data for leadership KPI visibility.

Power BI KPI Audit
06 policy

POA&M Remediation Engine

Managed POA&M register end-to-end, coordinating with engineering to close 15 findings in under two months. 90%+ resolved within target timelines.

POA&M GRC Remediation NIST
15 findings closed in 2mo
07 smart_toy

Vibe Coding

Developing AI-powered GRC compliance dashboard

AI GRC Compliance Dashboard

Credentials // Learning Journey

Education

2013 - 2017

B.Tech — Computer Science

JNTU Hyderabad

Professional Certifications

CompTIA Security+

Optum Corporate Training

CC — Cybersecurity

ISC2

SAFe Scrum Master 6.0

SAFe Agile

Azure Admin AZ-104

Udemy

CCSP — In Progress

ISC2

Initialize
Direct
Link

PHONE

(309) 612-6327

LOCATION

Bloomington, IL — Remote-First

AVAILABILITY